Security Advisory

CVE-2017-8360

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-05-12 06:54:00
Last updated 2024-08-05 16:34:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. This data is leaked via unintended channels: debug messages accessible to any process that is running in the current user session, and filesystem access to C:\Users\Public\MicTray.log by any process.